The Role
DevSecOps Pipeline Design & Implementation
- Design, build and maintain secure CI/CD pipelines integrating SAST, DAST, SCA, secrets detection, container scanning and SBOM generation as automated, non-blocking gates that shift security feedback to the point of code commit.
- Implement and tune security tooling (GitHub Advanced Security, Checkmarx, Snyk, Trivy, OWASP ZAP, IriusRisk or equivalent) in collaboration with ICS and the COE, balancing coverage against pipeline velocity.
- Define pipeline security standards, guardrails and paved-road templates that delivery teams can adopt without bespoke configuration, and maintain them as the threat landscape and tooling evolve.
Security Testing & Vulnerability Management
- Own the security testing practice for in-scope applications: plan and execute SAST, DAST, penetration testing support and API security testing, and validate remediation of findings through to closure.
- Triage and prioritise vulnerability findings from automated tooling and manual review, producing clear, risk-rated remediation guidance that engineering teams can act on without specialist interpretation.
- Track finding closure rates across the top platforms, reporting on open risk and recurring weakness themes to the CoE Lead, and escalating blockers where remediation is stalling.
Secure Coding Enablement & Developer Support
- Act as the primary hands-on security engineering resource for delivery teams: review pull requests for security weaknesses, pair with engineers on remediation, and provide just-in-time secure coding guidance.
- Build and maintain a secure coding standards library, covering OWASP, injection, authentication, authorisation, secrets management and cryptographic hygiene, mapped to the technology stacks in use across HWC.
- Run developer-facing security enablement sessions — secure code reviews, threat modelling walkthroughs, hands-on labs — to build security awareness at the point where vulnerabilities are introduced.
Build Integrity & Supply Chain Security
- Implement and operate build-integrity controls: artefact signing, provenance verification, dependency allow-listing and licence compliance checks integrated into CI/CD pipelines.
- Own software composition analysis (SCA) and SBOM generation across in-scope platforms, ensuring dependency and licence risk feeds directly into the technical risk profiling practice.
- Monitor for new CVEs and zero-day disclosures affecting in-scope technology stacks, assess impact, and coordinate rapid response with platform owners and ICS.
AI-Assisted Security Engineering
- Apply AI and automation (GenAI, GitHub Copilot, agent frameworks) to security engineering tasks — automated triage, finding summarisation, remediation suggestion, pipeline policy generation — with human-in-the-loop validation on outputs.
- Evaluate and pilot emerging AI-assisted security tooling in coordination with ICS and the CoE Lead, identifying where automation creates genuine capacity rather than adding cost or noise.
- Contribute to the CoE's broader AI-enablement programme by converting manual, analyst-dependent security steps into repeatable, tool-assisted engineering workflows.
Cloud Security Engineering
- Implement and validate Azure cloud security controls — identity and access management, network segmentation, secrets management (Key Vault), container and Kubernetes security, storage and data encryption — aligned to InfoSec and ICS standards.
- Conduct infrastructure-as-code (IaC) security reviews (Terraform, Bicep or equivalent), identifying misconfiguration risks before they reach production.
- Support cloud security posture management (CSPM) tooling adoption and alert triage in collaboration with ICS and platform teams.
Cross-COE Integration & Stakeholder Collaboration
- Work closely with the Threat Modelling & Risk Specialist to ensure threat model findings and technical risk profiles translate into concrete engineering controls and pipeline gates, closing the loop between assessment and implementation.
- Partner with the Security Architect to implement architectural review recommendations at the code, pipeline and infrastructure level, validating that design-time decisions are reflected in the running system.
- Collaborate with LOB platform owners, engineering leads and security champions to embed security tooling and practices into team workflows without becoming a dependency or bottleneck.
Governance, Reporting & Continuous Improvement
- Maintain an up-to-date view of security tooling coverage, pipeline gate effectiveness and finding-closure velocity across in-scope platforms, reporting to the COE Lead on a defined cadence.
- Identify recurring weaknesses and systemic tooling gaps, recommending and implementing improvements to pipeline controls, scanning rules and developer guidance rather than remediating issues one by one.
- Support evidence collation for InfoSec, ICS and audit (PwC) reviews, ensuring security engineering controls are documented, demonstrable and traceable to NIST, OWASP and SAMM requirements.
Requirements
Minimum Qualifications
- 8-12 years in technology, with 5+ years in application security engineering, DevSecOps or a security-engineering role with hands-on pipeline and tooling ownership.
- Demonstrable experience designing and operating DevSecOps pipelines: SAST, DAST, SCA, secrets detection, container scanning and SBOM generation integrated into CI/CD.
- Hands-on experience with security tooling (GitHub Advanced Security, Checkmarx, Snyk, Trivy, OWASP ZAP or equivalent) in enterprise engineering environments.
- Azure cloud security engineering knowledge: IAM, Key Vault, network controls, container/Kubernetes security, IaC scanning.
- Working knowledge of OWASP Top 10, NIST, secure coding principles and vulnerability management, with ability to translate findings into engineer-ready remediation guidance.
Preferred Qualifications
- Insurance or financial-services industry experience.
- Security certifications (CSSLP, CEH, OSCP, GWEB) and/or Azure security certifications (AZ-500, SC-100).
- Experience applying AI and automation to security engineering (GenAI-assisted triage, agentic pipelines, GitHub Copilot for secure code review).
- Experience enabling federated engineering teams and security champions at scale, across distributed LOB structures.